adwcleaner[r0]

Download AdwCleaner[R0]

If you can't read please download the document

Upload: mitch-speeder

Post on 20-Dec-2015

3 views

Category:

Documents


0 download

DESCRIPTION

nnnn

TRANSCRIPT

# AdwCleaner v3.017 - Report created 16/01/2014 at 22:24:32# Updated 12/01/2014 by Xplode# Operating System : Windows 7 Professional Service Pack 1 (32 bits)# Username : Transport - TRANSPORT-PC# Running from : C:\Users\Transport\Downloads\Programs\adwcleaner.exe# Option : Scan***** [ Services ] *****Service Found : WpmService Found : Yontoo Desktop Updater***** [ Files / Folders ] *****File Found : C:\Program Files\Mozilla Firefox\browser\searchplugins\Ask.xmlFile Found : C:\Program Files\Mozilla Firefox\searchplugins\Ask.xmlFile Found : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xmlFile Found : C:\Program Files\Mozilla Firefox\searchplugins\delta-homes.xmlFile Found : C:\Program Files\Mozilla Firefox\searchplugins\qvo6.xmlFile Found : C:\Users\Transport\AppData\Roaming\Mozilla\Firefox\Profiles\reqgiyh8.default\searchplugins\Ask.xmlFile Found : C:\Users\Transport\AppData\Roaming\Mozilla\Firefox\Profiles\reqgiyh8.default\searchplugins\delta.xmlFile Found : C:\Users\Transport\AppData\Roaming\Mozilla\Firefox\Profiles\reqgiyh8.default\searchplugins\WebSearch.xmlFile Found : C:\Users\Transport\AppData\Roaming\Mozilla\Firefox\Profiles\reqgiyh8.default\user.jsFile Found : C:\Windows\System32\Tasks\GoforFilesUpdateFolder Found : C:\Users\Transport\AppData\Local\Google\Chrome\User Data\Default\Extensions\jolpihgdojbefelfjebcocieacmbbpfaFolder Found : C:\Users\Transport\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmddklobnhooecpilodmkepnoofmopmiFolder Found : C:\Users\Transport\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmddklobnhooecpilodmkepnoofmopmiFolder Found : C:\Users\Transport\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndoogklpgbmpfbcighakgcgealhkbocaFolder Found : C:\Users\Transport\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjjFolder Found C:\Program Files\BrowseToSaveFolder Found C:\Program Files\continuetosaveFolder Found C:\Program Files\MinibarFolder Found C:\Program Files\SimilarSitesFolder Found C:\Program Files\ss helperFolder Found C:\Program Files\WebConnectFolder Found C:\Program Files\WebSearchFolder Found C:\ProgramData\BabylonFolder Found C:\ProgramData\Barowssei2savEFolder Found C:\ProgramData\BitGuardFolder Found C:\ProgramData\Browser ManagerFolder Found C:\ProgramData\BrowserProtectFolder Found C:\ProgramData\contienuetosaveFolder Found C:\ProgramData\DoWnlioaD akEeeperrFolder Found C:\ProgramData\eSafeFolder Found C:\ProgramData\SearchNewTabFolder Found C:\ProgramData\SearuCh-NewTaabFolder Found C:\ProgramData\SearuCh-NewTaabFolder Found C:\ProgramData\SoftSafeFolder Found C:\ProgramData\StarAppFolder Found C:\ProgramData\Tarma InstallerFolder Found C:\ProgramData\WinterSoftFolder Found C:\ProgramData\WPMFolder Found C:\ProgramData\WWeekappFolder Found C:\Users\Transport\AppData\Local\MinibarFolder Found C:\Users\Transport\AppData\Local\webplayerFolder Found C:\Users\Transport\AppData\LocalLow\Barowssei2savEFolder Found C:\Users\Transport\AppData\LocalLow\searchresultstbFolder Found C:\Users\Transport\AppData\Roaming\BabylonFolder Found C:\Users\Transport\AppData\Roaming\goforfilesFolder Found C:\Users\Transport\AppData\Roaming\SimilarSites***** [ Shortcuts ] *****Shortcut Found : C:\Users\Transport\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=&utm_content=sc&from=cor&uid=HitachiXHTS545016B9A300_091217PBPB06QCE75JDLX&ts=1377630693 )Shortcut Found : C:\Users\Transport\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player\Uninstall.lnk ( _?=C:\Users\Transport\AppData\Local\WebPlayer\FLV Player )Shortcut Found : C:\Users\Transport\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=&utm_content=sc&from=cor&uid=HitachiXHTS545016B9A300_091217PBPB06QCE75JDLX&ts=1377630693 )Shortcut Found : C:\Users\Transport\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=&utm_content=sc&from=cor&uid=HitachiXHTS545016B9A300_091217PBPB06QCE75JDLX&ts=1377630693 )Shortcut Found : C:\Users\Transport\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=&utm_content=sc&from=cor&uid=HitachiXHTS545016B9A300_091217PBPB06QCE75JDLX&ts=1377630693 )Shortcut Found : C:\Users\Transport\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ( hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=&utm_content=sc&from=cor&uid=HitachiXHTS545016B9A300_091217PBPB06QCE75JDLX&ts=1377630693 )***** [ Registry ] *****Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=&utm_content=sc&from=cor&uid=HitachiXHTS545016B9A300_091217PBPB06QCE75JDLX&ts=1377630693Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~1\sshelp~1\psupport.dllKey Found : HKCU\Software\APN PIPKey Found : HKCU\Software\AppDataLow\SProtectorKey Found : HKCU\Software\BabylonToolbarKey Found : HKCU\Software\BIKey Found : HKCU\Software\delta LTDKey Found : HKCU\Software\GoforFilesKey Found : HKCU\Software\InstallCoreKey Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2316C625-B487-4410-A1A5-FF040B65245F}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3444C3C5-6C56-4A16-A453-832B05BF6EA4}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D233FAD-4B9D-5D97-3590-FABC7F68082D}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA74D58F-ACD0-450D-A85E-6C04B171C044}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2316C625-B487-4410-A1A5-FF040B65245F}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3444C3C5-6C56-4A16-A453-832B05BF6EA4}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D233FAD-4B9D-5D97-3590-FABC7F68082D}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA74D58F-ACD0-450D-A85E-6C04B171C044}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile AppsKey Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\FLV PlayerKey Found : HKCU\Software\SoftonicKey Found : HKCU\Software\WebConnectKey Found : HKCU\Software\WebplayerKey Found : HKLM\Software\BabylonKey Found : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}Key Found : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}Key Found : HKLM\SOFTWARE\Classes\CLSID\{14F35FFC-522A-4DD1-A07E-6B8B65C6891E}Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}Key Found : HKLM\SOFTWARE\Classes\CLSID\{2316C625-B487-4410-A1A5-FF040B65245F}Key Found : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}Key Found : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}Key Found : HKLM\SOFTWARE\Classes\Interface\{7C28CEF1-A4A6-4B6A-8B97-C44F1267753C}Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}Key Found : HKLM\SOFTWARE\Classes\Prod.capKey Found : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D8CAF2DF-52D3-42CF-9DDB-F4FF828DB4F8}Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}Key Found : HKLM\Software\DataMngrKey Found : HKLM\Software\delta-homesSoftwareKey Found : HKLM\Software\GoforFilesKey Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfoKey Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3444C3C5-6C56-4A16-A453-832B05BF6EA4}Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCSKey Found : HKLM\SOFTWARE\Microsoft\Tracing\AskPIP_FF__RASAPI32Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskPIP_FF__RASMANCSKey Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32Key Found : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancsKey Found : HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASAPI32Key Found : HKLM\SOFTWARE\Microsoft\Tracing\GoforFiles_RASMANCSKey Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCSKey Found : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32Key Found : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancsKey Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\GoforFilesUpdateKey Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C894B86-8ACD-4719-9635-3076E2F788FD}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2316C625-B487-4410-A1A5-FF040B65245F}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3444C3C5-6C56-4A16-A453-832B05BF6EA4}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_360582d7Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebConnectKey Found : HKLM\Software\PIPKey Found : HKLM\Software\qvo6SoftwareKey Found : HKLM\Software\SafetyNutKey Found : HKLM\Software\SP GlobalKey Found : HKLM\Software\SProtectorKey Found : HKLM\Software\supWPMKey Found : HKLM\Software\Tarma InstallerKey Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvcValue Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{3444C3C5-6C56-4A16-A453-832B05BF6EA4}]Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]***** [ Browsers ] *****-\\ Internet Explorer v8.0.7601.17514Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=&utm_content=hp&from=cor&uid=HitachiXHTS545016B9A300_091217PBPB06QCE75JDLX&ts=1377630693Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=&utm_content=hp&from=cor&uid=HitachiXHTS545016B9A300_091217PBPB06QCE75JDLX&ts=1377630693Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://websearch.wisesearch.info/?pid=821&r=2013/10/27&hid=17114805336967448762&lg=EN&cc=ID&unqvl=39-\\ Mozilla Firefox v26.0 (en-US)[ File : C:\Users\Transport\AppData\Roaming\Mozilla\Firefox\Profiles\reqgiyh8.default\prefs.js ]Line Found : user_pref("aol_toolbar.default.homepage.check", false);Line Found : user_pref("aol_toolbar.default.search.check", false);Line Found : user_pref("browser.newtab.url", "hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=&utm_content=hp&from=cor&uid=HitachiXHTS545016B9A300_091217PBPB06QCE75JDLX&ts=1377630693");Line Found : user_pref("browser.search.defaultenginename,S", "WebSearch");Line Found : user_pref("browser.search.defaulturl", "hxxp://websearch.wisesearch.info/?pid=821&r=2013/10/27&hid=17114805336967448762&lg=EN&cc=ID&unqvl=39&l=1&q=");Line Found : user_pref("browser.search.order.1", "WebSearch");Line Found : user_pref("browser.search.order.1,S", "WebSearch");Line Found : user_pref("browser.search.selectedEngine,S", "WebSearch");Line Found : user_pref("extensions.5134aa0a22308.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}c[...]Line Found : user_pref("extensions.5143c6250f867.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}c[...]Line Found : user_pref("extensions.5143c88da48c4.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}c[...]Line Found : user_pref("extensions.51991a60ce5d3.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}c[...]Line Found : user_pref("extensions.BabylonToolbar.prtkDS", 0);Line Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);Line Found : user_pref("extensions.BabylonToolbar_i.newTab", true);Line Found : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.delta-search.com/?affID=119293&babsrc=NT_ss&mntrId=b8f37aee000000000000000000000000");Line Found : user_pref("extensions.delta.admin", false);Line Found : user_pref("extensions.delta.aflt", "babsst");Line Found : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");Line Found : user_pref("extensions.delta.autoRvrt", "false");Line Found : user_pref("extensions.delta.bbDpng", "7");Line Found : user_pref("extensions.delta.cntry", "ID");Line Found : user_pref("extensions.delta.dfltLng", "en");Line Found : user_pref("extensions.delta.excTlbr", false);Line Found : user_pref("extensions.delta.hdrMd5", "F5B4247FEC3FBFB9F0FDD0E76ACF3AAC");Line Found : user_pref("extensions.delta.id", "b8f37aee000000000000000000000000");Line Found : user_pref("extensions.delta.instlDay", "15768");Line Found : user_pref("extensions.delta.instlRef", "sst");Line Found : user_pref("extensions.delta.lastVrsnTs", "1.8.10.021:05:02");Line Found : user_pref("extensions.delta.newTab", false);Line Found : user_pref("extensions.delta.prdct", "delta");Line Found : user_pref("extensions.delta.prtnrId", "delta");Line Found : user_pref("extensions.delta.rvrt", "false");Line Found : user_pref("extensions.delta.sg", "azb");Line Found : user_pref("extensions.delta.smplGrp", "none");Line Found : user_pref("extensions.delta.tlbrId", "base");Line Found : user_pref("extensions.delta.tlbrSrchUrl", "");Line Found : user_pref("extensions.delta.vrsn", "1.8.10.0");Line Found : user_pref("extensions.delta.vrsnTs", "1.8.10.021:05:02");Line Found : user_pref("extensions.delta.vrsni", "1.8.10.0");Line Found : user_pref("[email protected]", true);Line Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "WebSearch");Line Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "WebSearch");Line Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://websearch.wisesearch.info/?pid=821&r=2013/10/27&hid=17114805336967448762&lg=EN&cc=ID&unqvl=39");Line Found : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://websearch.wisesearch.info/?pid=821&r=2013/10/27&hid=17114805336967448762&lg=EN&cc=ID&unqvl=39&l=1&q=");Line Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");Line Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");Line Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");Line Found : user_pref("sweetim.toolbar.searchguard.enable", "");Line Found : user_pref("browser.search.defaultenginename", "WebSearch");Line Found : user_pref("browser.search.selectedEngine", "WebSearch");-\\ Google Chrome v[ File : C:\Users\Transport\AppData\Local\Google\Chrome\User Data\Default\preferences ]Found : homepageFound : urls_to_restore_on_startup*************************AdwCleaner[R0].txt - [18068 octets] - [16/01/2014 22:24:32]########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [18129 octets] ##########